Skip to main content

Improper Neutralization of Input Terminators

CVE-2025-7962

Severity Medium
Score 6/10

Summary

In Jakarta Mail through 2.0.3 it is possible to preform a SMTP Injection by utilizing the"\r" and "\n" UTF-8 characters to separate different messages.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-147 - Improper Neutralization of Input Terminators

The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as input terminators when they are sent to a downstream component.

Advisory Timeline

  • Published